An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806). . MGASA-2019-0051 - Updated pdns-recursor package fixes security vulnerabilities Publication date: 23 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0051.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-3806, CVE-2019-3807 An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806). An issue has been found in PowerDNS Recursor where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation (CVE-2019-3807). References: - https://bugs.mageia.org/show_bug.cgi?id=24218 - https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-01.html - https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-02.html - https://www.cve.org/CVERecord?id=CVE-2019-3806 - https://www.cve.org/CVERecord?id=CVE-2019-3807 SRPMS: - 6/core/pdns-recursor-4.1.9-1.mga6 . PowerDNS Recursor resolves critical vulnerabilities in Mageia influencing DNS configurations. Learn about the remedies in MGASA-2019-0051.. PowerDNS Recursor Security, Mageia Security Update, DNSSEC Vulnerability Fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.